EP2339460B1 - Bereitstellung von Software-Verteilung und Aktualisierungsdiensten ungeachtet des Zustands oder des physischen Standorts einer Endpunktmaschine - Google Patents

Bereitstellung von Software-Verteilung und Aktualisierungsdiensten ungeachtet des Zustands oder des physischen Standorts einer Endpunktmaschine Download PDF

Info

Publication number
EP2339460B1
EP2339460B1 EP10252160.6A EP10252160A EP2339460B1 EP 2339460 B1 EP2339460 B1 EP 2339460B1 EP 10252160 A EP10252160 A EP 10252160A EP 2339460 B1 EP2339460 B1 EP 2339460B1
Authority
EP
European Patent Office
Prior art keywords
software
end point
3pds
point machine
ram
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
EP10252160.6A
Other languages
English (en)
French (fr)
Other versions
EP2339460A3 (de
EP2339460A2 (de
Inventor
Hormuzd M. Khosravi
Ajith K. Illendula
Ned M. Smith
Yasser Rasheed
Bryan K. Jorgensen
Tracie L. Zenti
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Intel Corp
Original Assignee
Intel Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Intel Corp filed Critical Intel Corp
Publication of EP2339460A2 publication Critical patent/EP2339460A2/de
Publication of EP2339460A3 publication Critical patent/EP2339460A3/de
Application granted granted Critical
Publication of EP2339460B1 publication Critical patent/EP2339460B1/de
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/65Updates
    • G06F8/654Updates using techniques specially adapted for alterable solid state memories, e.g. for EEPROM or flash memories
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/61Installation
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/65Updates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/104Peer-to-peer [P2P] networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 

Definitions

  • the type of software that may be provided after sale of the equipment may include drivers to provide new services and user applications, middleware, device firmware, and basic input/output systems.
  • the software may be provided by independent software vendors or by other third parties relative to the equipment vendor. Thus, these software vendors desire to provide the software to the end point machine users in the most efficient fashion possible. This problem is now addressed.
  • the present invention provides a method of downloading software, a method that is implemented by computer, in particular by an end point machine, to facilitate software distribution from a remote software source to said computer, a computer readable medium storing instructions to enable a computer to perform such a method, and a computer (the end point machine) that is to facilitate such software distribution, each as set forth in the independent claims among the claims appended hereto.
  • Figure 1 shows a computer or end point machine that may use software which may need to be updated.
  • an independent software vendor may wish to provide software updates to a large number of such systems that are distributed throughout the world.
  • a microcontroller 45 within a graphics and memory controller hub 44 houses a management engine 'ME' firmware to implement various services on behalf of management applications.
  • the non-volatile random access memory 28 houses the system's basic input/output system code used by a management engine and a third party data store '3PDS' that enable applications to store information as needed in non-volatile memory.
  • the memory 28 may be a flash memory in one embodiment.
  • the INTEL ® Active Management Technology 'AMT' is a silicon resident management mechanism for remote discovery, healing, and protection of computer systems. It may provide the basis for software solutions to address manageability issues, improve efficiency of remote management and asset inventory functionality and third party management software, safeguard functionality of critical agents from operating system failure, power loss, and intentional or inadvertent client removal.
  • the reader is referred to the entry in Wikipedia: "Intel Active Management Technology", 11 Nov. 2009, pages 1-6, XP55031269 , for further details.
  • the management engine which resides within the microcontroller 45, runs on auxiliary power and is available at all system power states.
  • the INTEL ® AMT technology allows management applications to access client computers, even when they are in a powered off state.
  • the non-volatile random access memory 28, which has storage space to store third party data, may be a highly configurable memory that is both persistent and protected. It provides a non-volatile memory space accessible by manageability applications even when the operating system 24 is unresponsive or management agents are missing.
  • the memory 28 is protected by control mechanisms that use an access control list to enforce access to the space, so only authorized remote devices or applications have access to the data stored there.
  • the INTEL ® AMT is a component of the INTEL ® vPro Workstation Platform of the type shown in Figure 1 . It may thus include a central processing unit 40 with software agents 42, and an operating system 24.
  • the graphics and memory controller hub 44 may be supported by dynamic random access memory 54 and 56, in some embodiments.
  • An I/O controller hub 46 may include filters 48, sensors 50, and a medium access control 'MAC' 52 coupled to the flash memory 28 in one embodiment.
  • a local area network 'LAN' controller 58 may be coupled to the hub 46. It may provide for wired local area networks, including an out-of-band connection 60 and a gigabit Ethernet connection 62, as well as wireless out-of-band connectivity 64, and IEEE 802.11 connectivity 66.
  • the INTEL ® AMT software package may also include a software distribution service or SDS module 20 on the end point 12 running operating system 'OS' 24.
  • the end point 12 may be part of a network 10 also including an update server 14. This module may enable future software installations.
  • the AMT firmware may be configured to allocate specific storage space for software distribution. In one embodiment, this area starts out with no data in it.
  • the 3PDS portion of the non-volatile random access memory 28 can be preconfigured to preserve an area for a given entity, such as an independent software vendor, to work with to define a structure to capture the information necessary for software provisioning.
  • the 3PDS portion of the non-volatile random access memory 28 may be provisioned with the correct software distribution information binary large object 'BLOB' based on the software distributor's request.
  • the BLOB can be implemented using information exchange servers or any central server on the Internet that works in connection with a software distribution server to get the appropriate provisioning BLOB or information.
  • AMT can connect to this remote provisioning server by default or based on a policy that is worked out with the software update provider. This can happen when the management system first boots up in the system.
  • a host embedded controller interface 'HECI' driver checks the 3PDS portion of the non-volatile random access memory 28 to find out if software needs to be provisioned by reading the configured region described above that contains the information BLOB, as indicated at 38. If the answer is yes, the HECI driver 22 triggers the SDS to start the software download process, as indicated at 32.
  • the SDS 20 queries the 3PDS and connects (over connect 34) to a virtual private network (VPN) software server 14 that has been provisioned in the 3PDS portion of the non-volatile random access memory 28.
  • the SDS module 20 talks to the server 14 and downloads and installs a software client 18 or a barebones installer for the update software, as examples.
  • the SDS verifies the downloaded package with the client 18 using a hash value stored in the 3PDS, as indicated in block 36.
  • the SDS or the update server 14 (for example, the gateway 16) marks the appropriate region in the 3PDS with a flag, indicating that no further download is needed and that the download has been completed, as indicated at 36.
  • the end user can use the already downloaded installer and finish downloading the full package, in some embodiments.
  • an extensible mechanism may be provided that can work with multiple software vendors. It may also give a choice to an information technology administrator to disable the SDS installation if he does not intend to use the distribution mechanism. In the future, if the customer wants the distribution mechanism, the customer can also start the SDS installer and the whole package can initiate itself.
  • a distribution service may be provided to enterprise clients using client initiated remote access (CIRA).
  • Some end points including those using the INTEL ® vPro technology have hardware, software, and firmware components to facilitate the end point's ability to contact the corporate network even if the machine is physically outside the firewall and the end point's host operating system is compromised.
  • These end point technologies rely on a software management presence server (MPS) placed in the enterprise demilitarized zone to broker communications between the end point and the enterprise information technology assets inside the firewalls.
  • MPS software management presence server
  • Software providers may provide distribution and update services for a variety of software including, as one example, a virtual private network client software to enterprise end points.
  • One implementation, specific to end points located outside the corporate firewall, provides a secure means to do so, while preserving the ability of the information technology administrator to manage software images on its end points.
  • the local manageability service 'LMS' 70 may correspond to the SDS 20 of the previous embodiment.
  • the LMS 70 provides the software distribution service functionality on the end point 12.
  • the 3PDS may be part of the non-volatile random access memory 28, providing a data store to store the software distribution BLOB, as described above.
  • An out-of-band Internet networking stack 30 may provide out-of-band communication stack and functionality. It may be an out-of-band channel provided through the AMT firmwarein one embodiment. It may implement the CIRA protocol and, in some embodiments, may also implement a virtual private network client and firmware.
  • the server 14a in this embodiment may be a VPN server with a VPN gateway 16a, which may also be a software management present server or MPS. It facilitates software distribution over the Internet.
  • the LMS 70 checks for software installation flags in the 3PDS portion of the non-volatile random access memory 28. Based on that flag, the LMS triggers an out-of-band CIRA connection to the remote server 14a, or to an MPS proxy server, that in turn communicates with the server 14a. This may be done using the HECI driver 22 and client 19, as indicated by the trigger arrow 72.
  • the client 19 may be an "AnyConnect Lite" VPN client, available from CISCO Systems, Inc., San Jose, CA 95134, in one embodiment.
  • the remote server 14a writes the hash of a software image in the 3PDS for verification, as indicated at 36.
  • the LMS also initiates an in-band, operating system based connection to the remote server, indicated at 74, that provides a software image for distribution.
  • the LMS downloads the software image from the remote server, as indicated at 32, resulting in the client 18a. It validates the image for the software with the hash value stored in the 3PDS to make sure that it is a valid image before it installs the software. Once the download is successful, the LMS or remote server/MPS resets the software install flag in the 3PDS, as indicated by the arrow 36.
  • the out-of-band communication link may be a management engine based networking stack that works independently of the host operating system stack.
  • the out-of-band communications link allows downloading of software regardless of the power state (on, hibernate, sleep, power down) of the host, regardless of the operating system state (up, down or corrupted) and regardless of host location (inside or outside of the enterprise).
  • ring zero 76 may be used. That is, the operating system kernel modules and drivers may be used to perform the software distribution functionality.
  • the SDS functionality 20 may be imbedded inside the HECI driver 22, in one embodiment.
  • a local area network/network interface card driver 78 may be used for network communication, in one embodiment over connection 80. The rest of the flow is the same described for Figure 2 , except for using the HECI driver based SDS functionality versus the ring 3 SDS windows service or application.
  • software may be distributed in a way that is independent of the current state or physical location of the platform to receive the software update.
  • the management engine may be used to help with software distribution, providing additional security assurances for software vendors.
  • a sequence may be implemented in software, hardware, or firmware.
  • the software may be stored in an optical, magnetic, or semiconductor memory.
  • it can be stored in one of the memories 54 or 56, shown in Figure 1 .
  • the memory may store a sequence of instructions that are executed by a computer, such as the microcontroller 45.
  • a check at block 82 determines whether the 3PDS portion of the non-volatile random access memory 28 is provisioned with a BLOB providing an identification of software updates or downloads. Then, typically on boot up, in block 84, a check is made to determine whether there is a BLOB and what the BLOB is. If there is a BLOB and there is no flag set to indicate the software was already downloaded, as determined in diamond 86, a software download is initiated, as indicated in block 88, and, otherwise, the flow ends. The download is verified, as indicated in block 90, and then, in block 92, the BLOB is marked to indicate that the software has been downloaded so that the next time the system starts up, it will not be downloaded again.
  • references throughout this specification to "one embodiment” or “an embodiment” mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one implementation encompassed within the present invention. Thus, appearances of the phrase “one embodiment” or “in an embodiment” are not necessarily referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be instituted in other suitable forms other than the particular embodiment illustrated and all such forms may be encompassed within the claims of the present application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Information Transfer Between Computers (AREA)
  • Stored Programmes (AREA)
  • Debugging And Monitoring (AREA)

Claims (9)

  1. Verfahren zum Herunterladen von Software (32) von einem entfernten Server (14, 14a) zu einer Endpunktmaschine (12), unabhängig von dem Zustand oder dem physischen Standort der Endpunktmaschine, wobei die folgenden maschinenimplementierten Schritte durch ein Steuergerät (45, 46) mit Hilfsstromversorgung an der Endpunktmaschine (12) durchgeführt werden:
    Speichern (82) einer Anzeige in einem Drittanbieter-Datenspeicher (Third-Party Data Store, 3PDS) in einem nichtflüchtigen Direktzugriffsspeicher (Non-Volatile Random Access Memory, NV-RAM) (28) der Endpunktmaschine, dass die Software zum Herunterladen verfügbar ist;
    Prüfen (84, 86) des 3PDS des NV-RAM (28) der Endpunktmaschine (12) hinsichtlich der Anzeige, dass Software (32) zum Herunterladen verfügbar ist, durch Prüfen, ob ein binäres großes Objekt in dem 3PDS des NV-RAM (28) bereitgestellt ist;
    Prüfen (86), ob der 3PDS des NV-RAM (28) markiert wurde, um anzuzeigen, dass die angezeigte Software (32) bereits heruntergeladen wurde;
    Einleiten (88) des Herunterladens der angezeigten Software durch eine bandexterne Kommunikationsverbindung (60), wenn durch das Prüfen des Markierens (86) bestätigt wird, dass die angezeigte Software (32) noch nicht heruntergeladen wurde; und
    Markieren (92) des 3PDS des NV-RAM (28), um anzuzeigen, dass die angezeigte Software heruntergeladen wurde.
  2. Verfahren nach Anspruch 1, wobei das Prüfen (84, 86) hinsichtlich des binären großen Objekts das Identifizieren (86) in dem binären großen Objekt der herunterzuladenden Software (32) einschließt.
  3. Verfahren nach Anspruch 2 einschließlich eines maschinenimplementierten Schritts des Verifizierens (90) der heruntergeladenen Software (32) an der Endpunktmaschine (12).
  4. Verfahren nach Anspruch 2, wobei die Markierung (92) des 3PDS des NV-RAM (28) darin besteht, den 3PDS mit einem Kennzeichen zu markieren, um anzuzeigen, dass die im binären großen Objekt angezeigte Software heruntergeladen wurde.
  5. Verfahren nach Anspruch 1 einschließlich eines maschinenimplementierten Schritts des automatischen Prüfens (84, 86) hinsichtlich herunterzuladender Software (32) jedes Mal, wenn die Endpunktmaschine (12) gestartet wird.
  6. Verfahren nach Anspruch 1, wobei das Herunterladen der Software (32) unter Verwendung eines durch einen Client eingeleiteten Fernzugriffs durchgeführt wird.
  7. Verfahren nach Anspruch 1 einschließlich der Endpunktmaschine (12), die Ring Null zum Herunterladen der Software (32) verwendet.
  8. Computerlesbares Medium, das Anweisungen speichert, um einen Computer in die Lage zu versetzen, das Verfahren nach einem der Ansprüche 1 bis 7 durchzuführen.
  9. Computer (12), der konfiguriert ist, um Software (32) von einem entfernten Server (14, 14a) unabhängig von dem Zustand oder dem physischen Standort des Computers herunterzuladen, wobei der Computer Folgendes umfasst:
    eine bandexterne Netzwerkverbindung (60) zum Bereitstellen einer Kommunikationsverbindung zwischen dem Computer und einem entfernten Server (14, 14a);
    ein Steuergerät (45, 46), das eine Hilfsstromversorgung aufweist;
    einen nichtflüchtigen Direktzugriffsspeicher (Non-Volatile Random Access Memory, NV-RAM) (28), auf den durch das Steuergerät (45, 46) zugegriffen werden kann und der einen Drittanbieter-Datenspeicher aufweist, um eine Anzeige von herunterzuladender Software (32) einzuschließen;
    einen dynamischen Direktzugriffsspeicher (56); und
    ein computerlesbares Medium (42), das Anweisungen speichert, die von diesem an den dynamischen Direktzugriffsspeicher (56) übertragbar sind und die von dem Steuergerät (45, 46) ausführbar sind, um die in einem der Ansprüche 1 bis 7 dargelegte Folge von Schritten auszuführen.
EP10252160.6A 2009-12-21 2010-12-17 Bereitstellung von Software-Verteilung und Aktualisierungsdiensten ungeachtet des Zustands oder des physischen Standorts einer Endpunktmaschine Active EP2339460B1 (de)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
US12/642,911 US8893112B2 (en) 2009-12-21 2009-12-21 Providing software distribution and update services regardless of the state or physical location of an end point machine

Publications (3)

Publication Number Publication Date
EP2339460A2 EP2339460A2 (de) 2011-06-29
EP2339460A3 EP2339460A3 (de) 2012-08-08
EP2339460B1 true EP2339460B1 (de) 2017-05-17

Family

ID=43973177

Family Applications (1)

Application Number Title Priority Date Filing Date
EP10252160.6A Active EP2339460B1 (de) 2009-12-21 2010-12-17 Bereitstellung von Software-Verteilung und Aktualisierungsdiensten ungeachtet des Zustands oder des physischen Standorts einer Endpunktmaschine

Country Status (5)

Country Link
US (1) US8893112B2 (de)
EP (1) EP2339460B1 (de)
JP (1) JP5302288B2 (de)
KR (1) KR101235520B1 (de)
CN (2) CN109918085B (de)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8301727B1 (en) * 2010-02-19 2012-10-30 Mcafee, Inc. System, method, and computer program product for receiving security content utilizing a serial over LAN connection
US9015455B2 (en) * 2011-07-07 2015-04-21 Intel Corporation Processsor integral technologies for BIOS flash attack protection and notification
US10009318B2 (en) 2012-03-14 2018-06-26 Microsoft Technology Licensing, Llc Connecting to a cloud service for secure access
US9135445B2 (en) * 2012-03-19 2015-09-15 Google Inc. Providing information about a web application or extension offered by website based on information about the application or extension gathered from a trusted site
JP5533935B2 (ja) * 2012-05-10 2014-06-25 トヨタ自動車株式会社 ソフトウェア配信システム、ソフトウェア配信方法
WO2014150753A2 (en) * 2013-03-15 2014-09-25 Openpeak Inc. Method and system for restricting the operation of applications to authorized domains
US10303456B2 (en) * 2017-03-23 2019-05-28 Intel Corporation Technologies for performing energy efficient software distribution
CN109495433B (zh) * 2017-09-13 2021-05-14 腾讯科技(深圳)有限公司 数据下载方法和装置、存储介质及电子装置
US10791019B2 (en) 2017-12-28 2020-09-29 Intel Corporation Edge or fog gateway assisted out-of-band remote management for managed client devices
US20210117172A1 (en) * 2019-10-21 2021-04-22 Pccw Vuclip (Singapore) Pte. Ltd. Data-driven consumer journey optimzation system for adaptive consumer applications

Family Cites Families (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5796952A (en) * 1997-03-21 1998-08-18 Dot Com Development, Inc. Method and apparatus for tracking client interaction with a network resource and creating client profiles and resource database
US20010044736A1 (en) * 1999-12-08 2001-11-22 Jacobs Paul E. E-mail software and method and system for distributing advertisements to client devices that have such e-mail software installed thereon
CA2357382A1 (en) * 2001-09-17 2003-03-17 Soma Networks, Inc. Software update method, apparatus and system
CN1234239C (zh) * 2002-09-30 2005-12-28 北京中视联数字系统有限公司 数字电视广播中的软件下载方法
JP2004164115A (ja) 2002-11-11 2004-06-10 Sharp Corp プログラム更新システムならびにこのプログラム更新システムに使用する更新管理装置および端末機
CN1331365C (zh) * 2002-12-31 2007-08-08 北京信威通信技术股份有限公司 无线通信系统终端软件自动升级的方法及系统
CN1186723C (zh) * 2003-01-29 2005-01-26 西安海星现代科技股份有限公司 基于软件令牌的适用于网络的动态口令身份认证系统
CN100543676C (zh) * 2003-12-18 2009-09-23 大同股份有限公司 固件更新的方法
US20050160474A1 (en) 2004-01-15 2005-07-21 Fujitsu Limited Information processing device and program
KR100584448B1 (ko) * 2004-01-19 2006-05-26 삼성전자주식회사 바이너리 위치정보를 이용한 임베디드 소프트웨어 원격다운로드방법 및 시스템
US7716660B2 (en) * 2004-12-14 2010-05-11 Microsoft Corporation Method and system for downloading updates
KR20060068558A (ko) * 2004-12-16 2006-06-21 엘지전자 주식회사 휴대 단말기를 위한 펌웨어 업그레이드 방법
JP2007034913A (ja) * 2005-07-29 2007-02-08 Kyocera Mita Corp 電気機器
US8295157B1 (en) * 2006-04-10 2012-10-23 Crimson Corporation Systems and methods for using out-of-band protocols for remote management while in-band communication is not available
RU2388045C2 (ru) * 2006-06-19 2010-04-27 Самсунг Электроникс Ко., Лтд. Система и способ обновления программы для переносного устройства с поддержкой ота
CN100456246C (zh) * 2007-01-23 2009-01-28 北京映翰通网络技术有限公司 一种固件程序升级的方法与装置
US20090019435A1 (en) 2007-07-12 2009-01-15 Sauer-Danfoss Inc. System and method for over the air programming
CN101207729B (zh) * 2007-12-17 2010-04-07 深圳市同洲电子股份有限公司 一种数字电视接收终端及其软件升级系统
CN101271396A (zh) * 2008-04-15 2008-09-24 威盛电子股份有限公司 电子装置及其在线更新固件的方法
JP4991668B2 (ja) * 2008-09-29 2012-08-01 株式会社東芝 コンピュータシステムおよび修正パッチ確認/適用方法

Also Published As

Publication number Publication date
EP2339460A3 (de) 2012-08-08
KR101235520B1 (ko) 2013-02-21
CN109918085A (zh) 2019-06-21
CN102104624A (zh) 2011-06-22
JP5302288B2 (ja) 2013-10-02
CN102104624B (zh) 2019-01-08
EP2339460A2 (de) 2011-06-29
US20110154316A1 (en) 2011-06-23
KR20110073316A (ko) 2011-06-29
US8893112B2 (en) 2014-11-18
JP2011129105A (ja) 2011-06-30
CN109918085B (zh) 2023-04-07

Similar Documents

Publication Publication Date Title
EP2339460B1 (de) Bereitstellung von Software-Verteilung und Aktualisierungsdiensten ungeachtet des Zustands oder des physischen Standorts einer Endpunktmaschine
EP2973147B1 (de) Richtlinienbasierter sicherer web-start
CN107534647B (zh) 用于传送启动脚本的系统、计算设备和存储介质
US8402528B1 (en) Portable firewall adapter
US8856875B2 (en) Software delivery models
US20030018763A1 (en) Systems and methods for software distribution and management
US11269655B2 (en) Bare metal device management
EP2717518B1 (de) Verfahren zum Datenschutz zwischen Geräten, die mit einem Netzwerk verbunden sind, und entsprechende Vorrichtung
US20070130624A1 (en) Method and system for a pre-os quarantine enforcement
WO2013169268A1 (en) Device lock for transit
EP2262169B1 (de) Konfiguration eines Endgerätes durch einen Router.
US20100275251A1 (en) Transferring credential information
EP3462305A1 (de) Aktualisierung von ecu und peripheriegeräten unter verwendung einer zentralen abfertigungseinheit
US9760528B1 (en) Methods and systems for creating a network
US7577996B1 (en) Apparatus, method and system for improving network security
US20160321132A1 (en) Receiving an update code prior to completion of a boot procedure
US11218441B2 (en) Use of a network address by a network accessory
US10579361B1 (en) Systems and methods for efficiently updating software installed on network devices
US11157609B1 (en) Apparatus, system, and method for secure execution of unsigned scripts
US11995450B2 (en) Cloud-based provisioning of UEFI-enabled systems
Burgess Learn RouterOS
US8296406B2 (en) Configurable device replacement
US20220377495A1 (en) Information processing apparatus and information processing method
US12105863B2 (en) Interface controller for commodity devices

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20110112

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

PUAL Search report despatched

Free format text: ORIGINAL CODE: 0009013

AK Designated contracting states

Kind code of ref document: A3

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

RIC1 Information provided on ipc code assigned before grant

Ipc: G06F 9/445 20060101AFI20120704BHEP

17Q First examination report despatched

Effective date: 20140110

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: GRANT OF PATENT IS INTENDED

INTG Intention to grant announced

Effective date: 20161205

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: INTEL CORPORATION

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

GRAA (expected) grant

Free format text: ORIGINAL CODE: 0009210

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE PATENT HAS BEEN GRANTED

AK Designated contracting states

Kind code of ref document: B1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

REG Reference to a national code

Ref country code: GB

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: CH

Ref legal event code: EP

REG Reference to a national code

Ref country code: IE

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: AT

Ref legal event code: REF

Ref document number: 895050

Country of ref document: AT

Kind code of ref document: T

Effective date: 20170615

REG Reference to a national code

Ref country code: DE

Ref legal event code: R096

Ref document number: 602010042384

Country of ref document: DE

REG Reference to a national code

Ref country code: NL

Ref legal event code: FP

REG Reference to a national code

Ref country code: SE

Ref legal event code: TRGR

REG Reference to a national code

Ref country code: LT

Ref legal event code: MG4D

REG Reference to a national code

Ref country code: AT

Ref legal event code: MK05

Ref document number: 895050

Country of ref document: AT

Kind code of ref document: T

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: ES

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: HR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: GR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170818

Ref country code: AT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: LT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: NO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170817

REG Reference to a national code

Ref country code: FR

Ref legal event code: PLFP

Year of fee payment: 8

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: LV

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170917

Ref country code: BG

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170817

Ref country code: RS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: PL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: EE

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: DK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: CZ

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: SK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: RO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

REG Reference to a national code

Ref country code: DE

Ref legal event code: R097

Ref document number: 602010042384

Country of ref document: DE

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: SM

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PLBE No opposition filed within time limit

Free format text: ORIGINAL CODE: 0009261

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

26N No opposition filed

Effective date: 20180220

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SI

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: FI

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171217

REG Reference to a national code

Ref country code: CH

Ref legal event code: PL

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171218

REG Reference to a national code

Ref country code: IE

Ref legal event code: MM4A

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MT

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171217

Ref country code: LU

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171217

REG Reference to a national code

Ref country code: BE

Ref legal event code: MM

Effective date: 20171231

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171217

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: BE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171231

Ref country code: LI

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171231

Ref country code: CH

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20171231

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MC

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

Ref country code: HU

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO

Effective date: 20101217

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: CY

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: TR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: PT

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: AL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20170517

P01 Opt-out of the competence of the unified patent court (upc) registered

Effective date: 20230518

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: NL

Payment date: 20230925

Year of fee payment: 14

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: FR

Payment date: 20230921

Year of fee payment: 14

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: GB

Payment date: 20231006

Year of fee payment: 14

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: DE

Payment date: 20230919

Year of fee payment: 14